Junglewise Threat Intelligence

CVE-2026-45089: hahwul Dalfox unauthenticated arbitrary file write in REST API server mode

CVE-2026-45089 · Severity: high · CVSS 8.2 · Published 2026-05-27

Technologies: github.com/hahwul/dalfox/v2 (Go), github.com/hahwul/dalfox (Go), Hahwul Dalfox. Vendors: Go, Hahwul.

Executive brief

Dalfox, a tool used for scanning web applications for vulnerabilities, contains a flaw in its server mode that allows unauthenticated users to create or modify files on the host system. By sending a specially crafted request to the Dalfox API, an attacker can force the application to write log data to any file path they choose. This could lead to system instability, corruption of critical configuration files, or potentially allow an attacker to gain further access to the server.

Technical details

Dalfox's REST API server mode fails to authenticate requests by default and does not sanitize the 'output', 'output-all', and 'debug' fields in the model.Options struct. When a scan is initiated via the API, these attacker-controlled fields are passed to the logging component. The logger opens the specified file path using os.O_APPEND|os.O_CREATE|os.O_WRONLY without verifying if the application is running in library/server mode. An unauthenticated remote attacker can exploit this to create new files or append log data (which includes the attacker-supplied URL) to existing files anywhere the process has write permissions. This vulnerability is rooted in CWE-306 (Missing Authentication) and CWE-73 (External Control of File Name or Path). Version 2.13.0 addresses this issue.

Affected products

  • hahwul Dalfox <= 2.12.0

Timeline

  • 2026-05-07: disclosed: Initial disclosure on GitHub Advisory Database
  • 2026-05-12: advisory: Advisory published
  • 2026-06-08: other: Advisory updated

References

Related threats